detections: - content: Windows Remote Access Software Hunt removed_in_version: 5.8.0 reason: Detection has been replaced by a new detection with a more specific name and logic replacement_content: - Detect Remote Access Software Usage Process - content: CertUtil Download With URLCache and Split Arguments removed_in_version: 5.8.0 reason: Detection deprecated in favor of "Windows File Download Via CertUtil", in order to provide a better experience of the alert replacement_content: - Windows File Download Via CertUtil - content: Windows CertUtil Download With URL Argument removed_in_version: 5.8.0 reason: Detection deprecated in favor of "Windows File Download Via CertUtil", in order to provide a better experience of the alert replacement_content: - Windows File Download Via CertUtil - content: CertUtil Download With VerifyCtl and Split Arguments removed_in_version: 5.8.0 reason: Detection deprecated in favor of "Windows File Download Via CertUtil", in order to provide a better experience of the alert replacement_content: - Windows File Download Via CertUtil - content: Detect Large Outbound ICMP Packets removed_in_version: 5.6.0 reason: Detection has been replaced by a new detection with a more specific name replacement_content: - Detect Large ICMP Traffic - content: Windows Service Created Within Public Path removed_in_version: 5.6.0 reason: Detection has been replaced by a new detection with a more specific name replacement_content: - Windows Service Created with Suspicious Service Path - content: GitHub Actions Disable Security Workflow removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - GitHub Organizations Disable Classic Branch Protection Rule - content: Github Commit Changes In Master removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Github Commit In Develop removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: GitHub Dependabot Alert removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - GitHub Enterprise Disable Dependabot - content: GitHub Pull Request from Unknown User removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Known Services Killed by Ransomware removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Security And Backup Services Stop - content: Remote Desktop Network Bruteforce removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Remote Desktop Network Bruteforce Attempt - content: Suspicious Driver Loaded Path removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Suspicious Driver Loaded Path - content: Suspicious Event Log Service Behavior removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Event Logging Service Has Shutdown - content: Suspicious Process File Path removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Suspicious Process File Path - content: AWS Cross Account Activity From Previously Unseen Account removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: aws detect attach to role policy removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: aws detect permanent key creation removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: aws detect role creation removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: aws detect sts assume role abuse removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: aws detect sts get session token abuse removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: AWS SAML Access by Provider User and Principal removed_in_version: 5.4.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: ASL AWS Excessive Security Scanning removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: AWS Cloud Provisioning From Previously Unseen Region removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Provisioning Activity From Previously Unseen Region - content: First time seen command line argument removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Windows connhost exe started forcefully removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Detect Mimikatz Using Loaded Images removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Kubernetes Azure detect sensitive role access removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Web Fraud - Anomalous User Clickspeed removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: EC2 Instance Started With Previously Unseen Instance Type removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Compute Instance Created With Previously Unseen Instance Type - content: EC2 Instance Started With Previously Unseen AMI removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Compute Instance Created With Previously Unseen Image - content: Domain Group Discovery With Net removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Group Discovery Via Net - content: Kubernetes AWS detect sensitive role access removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Winword Spawning Windows Script Host removed_in_version: 5.2.0 reason: "The following analytics was deprecated in favour of a more generic approach. Where instead of creating specific analytic for every potentially suspicious child of an office product. We group them by threat level.\nThis would ease management and false positives tuning." replacement_content: - Windows Office Product Spawned Uncommon Process - content: Winword Spawning PowerShell removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - content: Attempted Credential Dump From Registry via Reg exe removed_in_version: 5.2.0 reason: This analytic had some overlap with another one, hence the deprecation. It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry Hive Dump Via CommandLine replacement_content: - Windows Sensitive Registry Hive Dump Via CommandLine - content: Detect processes used for System Network Configuration Discovery removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Potential System Network Configuration Discovery Activity - content: Execution of File With Spaces Before Extension removed_in_version: 5.2.0 reason: Updated to a new detection name replacement_content: - Execution of File with Multiple Extensions - content: EC2 Instance Started In Previously Unseen Region removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Compute Instance Created In Previously Unused Region - content: Office Document Spawned Child Process To Download removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Office Product Spawned Child Process For Download - content: Detect new API calls from user roles removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud API Calls From Previously Unseen User Roles - content: Cmdline Tool Not Executed In CMD Shell removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Cmdline Tool Execution From Non-Shell Process - content: Linux Auditd Find Private Keys removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Linux Auditd Private Keys and Certificate Enumeration - content: Detect AWS API Activities From Unapproved Accounts removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Monitor DNS For Brand Abuse removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Kubernetes GCP detect sensitive object access removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Kubernetes Azure scan fingerprint removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: ASL AWS Password Policy Changes removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: O365 Suspicious Admin Email Forwarding removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - O365 Mailbox Email Forwarding Enabled - content: AWS Cloud Provisioning From Previously Unseen City removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Provisioning Activity From Previously Unseen City - content: Kubernetes AWS detect service accounts forbidden failure access removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Osquery pack - ColdRoot detection removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Windows Modify Registry Reg Restore removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Registry Entries Restored Via Reg - content: Kubernetes GCP detect most active service accounts by pod removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Scheduled tasks used in BadRabbit ransomware removed_in_version: 5.2.0 reason: Updated to a new detection name replacement_content: - Scheduled Task Deleted Or Created via CMD - content: Suspicious Rundll32 Rename removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Remote System Discovery with Net removed_in_version: 5.2.0 reason: "This analytic was focusing on 2 separate and unrelated type of threats or actions. PLease use the replacement content" replacement_content: - Windows Sensitive Group Discovery With Net - content: DNS Query Requests Resolved by Unauthorized DNS Servers removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Suspicious Changes to File Associations removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: GCP Detect high risk permissions by resource and account removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Office Product Writing cab or inf removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Office Product Dropped Cab or Inf File - content: Identify New User Accounts removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Office Product Spawn CMD Process removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - content: Windows DLL Search Order Hijacking Hunt removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Windows DLL Search Order Hijacking Hunt with Sysmon - content: ASL AWS CreateAccessKey removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - ASL AWS Create Access Key - content: Okta ThreatInsight Login Failure with High Unknown users removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Detect Spike in Security Group Activity removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Abnormally High Number Of Cloud Security Group API Calls - content: Office Product Spawning BITSAdmin removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - content: Create local admin accounts using net exe removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Create Local Administrator Account Via Net - content: Abnormally High AWS Instances Terminated by User - MLTK removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Windows Office Product Spawning MSDT removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Office Product Spawned MSDT - content: Detect Spike in AWS API Activity removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Office Product Spawning Windows Script Host removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - content: Prohibited Software On Endpoint removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Attacker Tools On Endpoint - content: AWS Cloud Provisioning From Previously Unseen Country removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Provisioning Activity From Previously Unseen Country - content: Detect Critical Alerts from Security Tools removed_in_version: 5.2.0 reason: As discussed internally, this analytic was too generic for an analyst to do anything with it. It was deprecated in favor of the more specific approach provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender Incident Alerts. Going forward analytics from leveraging alerts from vendors will have their specific analytics. replacement_content: - Microsoft Defender ATP Alerts - Microsoft Defender Incident Alerts - content: Excel Spawning PowerShell removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - content: Office Application Spawn rundll32 process removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - content: Excessive Usage Of Net App removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Excessive Usage Of Net App - content: Elevated Group Discovery With Net removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Sensitive Group Discovery With Net - content: Local Account Discovery with Net removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows User Discovery Via Net - content: Windows Command Shell Fetch Env Variables removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows List ENV Variables Via SET Command From Uncommon Parent - content: Suspicious Email - UBA Anomaly removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Detect web traffic to dynamic domain providers removed_in_version: 5.2.0 reason: Updated to use a different log source replacement_content: - Detect hosts connecting to dynamic domain providers - content: Okta Failed SSO Attempts removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta Unauthorized Access to Application - content: Kubernetes AWS detect RBAC authorization by account removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Kubernetes Azure detect service accounts forbidden failure access removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Remote Registry Key modifications removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: O365 Suspicious User Email Forwarding removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - O365 Mailbox Email Forwarding Enabled - content: Office Product Spawning MSHTA removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - content: Kubernetes AWS detect most active service accounts by pod removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Correlation by Repository and Risk removed_in_version: 5.2.0 reason: Detections updated to use the datamodel replacement_content: - Risk Rule for Dev Sec Ops by Repository - content: Kubernetes Azure detect RBAC authorization by account removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Clients Connecting to Multiple DNS Servers removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Excessive Service Stop Attempt removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Excessive Service Stop Attempt - content: Multiple Okta Users With Invalid Credentials From The Same IP removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta Multiple Users Failing To Authenticate From Ip - content: Suspicious writes to System Volume Information removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Detect new user AWS Console Login removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Detect AWS Console Login by New User - content: Domain Account Discovery With Net App removed_in_version: 5.2.0 reason: "This analytic was a TTP that looked only for commands that tries to query info about the users via net user /do. This had a couple of issues, such as triggering on creation of users via the /add flag etc..\nIt was deprecated in favor of a more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122" replacement_content: - Windows User Discovery Via Net - content: Detection of DNS Tunnels removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Detect DNS requests to Phishing Sites leveraging EvilGinx2 removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Office Document Creating Schedule Task removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Office Product Loading Taskschd DLL - content: Okta Account Locked Out removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta Multiple Accounts Locked Out - content: Unsuccessful Netbackup backups removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Detect Mimikatz Via PowerShell And EventCode 4703 removed_in_version: 5.2.0 reason: Updated to a new detection name replacement_content: - Detect Mimikatz With PowerShell Script Block Logging - content: Winword Spawning Cmd removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - content: GCP Kubernetes cluster scan detection removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Kubernetes Scanning by Unauthenticated IP Address - content: Kubernetes GCP detect suspicious kubectl calls removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: gcp detect oauth token abuse removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Correlation by User and Risk removed_in_version: 5.2.0 reason: Detections updated to use the datamodel replacement_content: - Risk Rule for Dev Sec Ops by Repository - content: Processes created by netsh removed_in_version: 5.2.0 reason: Updated to a new detection name replacement_content: - Processes launching netsh - content: Office Product Spawning Wmic removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - content: Extraction of Registry Hives removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Sensitive Registry Hive Dump Via CommandLine - content: Attempt To Stop Security Service removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Attempt To Stop Security Service - content: Windows MSIExec With Network Connections removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows HTTP Network Communication From MSIExec - content: Windows Query Registry Reg Save removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Registry Entries Exported Via Reg - content: Cloud Network Access Control List Deleted removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - AWS Network Access Control List Deleted - content: O365 Suspicious Rights Delegation removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - O365 Elevated Mailbox Permission Assigned - content: Abnormally High AWS Instances Launched by User - MLTK removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Reg exe used to hide files directories via registry keys removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Detect Long DNS TXT Record Response removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Password Policy Discovery with Net removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Password Policy Discovery with Net - content: AWS Cloud Provisioning From Previously Unseen IP Address removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Provisioning Activity From Previously Unseen IP Address - content: Network Connection Discovery With Net removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Network Connection Discovery Via Net - content: Kubernetes Azure detect suspicious kubectl calls removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Kubernetes GCP detect sensitive role access removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Detect Webshell Exploit Behavior removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Suspicious Child Process Spawned From WebServer - content: DNS record changed removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Unsigned Image Loaded by LSASS removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Detect USB device insertion removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Windows Network Share Interaction With Net removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Network Share Interaction Via Net - content: Account Discovery With Net App removed_in_version: 5.2.0 reason: This analytic was a TTP that focused on unrelated things and called account discovery. Since there were other detection that overlapped with it. I choose to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122 / Windows Excessive Usage Of Net App. replacement_content: - Windows Excessive Usage Of Net App - content: Change Default File Association removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows New Default File Association Value Set - content: Windows Lateral Tool Transfer RemCom removed_in_version: 5.2.0 reason: Updated to a new detection name replacement_content: - Windows Service Execution RemCom - content: Office Document Executing Macro Code removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Office Product Loading VBE7 DLL - content: Okta Account Lockout Events removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta Multiple Accounts Locked Out - content: Abnormally High AWS Instances Launched by User removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Abnormally High Number Of Cloud Instances Launched - content: EC2 Instance Modified With Previously Unseen User removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud API Calls From Previously Unseen User Roles - content: Windows Valid Account With Never Expires Password removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Set Account Password Policy To Unlimited Via Net - content: Windows hosts file modification removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: MSHTML Module Load in Office Product removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Office Product Loaded MSHTML Module - content: Abnormally High AWS Instances Terminated by User removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Abnormally High Number Of Cloud Instances Destroyed - content: Web Fraud - Account Harvesting removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Office Spawning Control removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Office Product Spawned Control - content: Detect Activity Related to Pass the Hash Attacks removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Deleting Of Net Users removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows User Deletion Via Net - content: Suspicious File Write removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: AWS EKS Kubernetes cluster sensitive object access removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Kubernetes Abuse of Secret by Unusual Location - content: Spectre and Meltdown Vulnerable Systems removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: EC2 Instance Started With Previously Unseen User removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Cloud Compute Instance Created By Previously Unseen User - content: Office Product Spawning CertUtil removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - content: Kubernetes GCP detect RBAC authorizations by account removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Office Application Drop Executable removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Office Product Dropped Uncommon File - content: Kubernetes Azure active service accounts by pod namespace removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Kubernetes Azure pod scan fingerprint removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Detect Spike in Network ACL Activity removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Abnormally High Number Of Cloud Infrastructure API Calls - content: Suspicious Powershell Command-Line Arguments removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Malicious PowerShell Process - Encoded Command - content: Office Application Spawn Regsvr32 process removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Windows Office Product Spawned Uncommon Process - content: Detect API activity from users without MFA removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - AWS Successful Single-Factor Authentication - content: Kubernetes Azure detect sensitive object access removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Web Fraud - Password Sharing Across Accounts removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Disabling Net User Account removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows User Disabled Via Net - content: GCP Detect accounts with high risk roles by project removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Kubernetes GCP detect service accounts forbidden failure access removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Extended Period Without Successful Netbackup Backups removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Office Product Spawning Rundll32 with no DLL removed_in_version: 5.2.0 reason: Renamed and updated logic replacement_content: - Windows Office Product Spawned Rundll32 With No DLL - content: Okta ThreatInsight Suspected PasswordSpray Attack removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta ThreatInsight Threat Detected - content: Net Localgroup Discovery removed_in_version: 5.2.0 reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44 / Windows Group Discovery Via Net replacement_content: - Windows Group Discovery Via Net - content: Uncommon Processes On Endpoint removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Attacker Tools On Endpoint - content: Dump LSASS via procdump Rename removed_in_version: 5.2.0 reason: Updated to a new detection name replacement_content: - Dump LSASS via procdump - content: Okta Two or More Rejected Okta Pushes removed_in_version: 5.2.0 reason: Detections updated to use the new search logic and field names due to the TA update replacement_content: - Okta Multiple Failed MFA Requests For User - content: Windows Service Stop Via Net and SC Application removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity - content: Excel Spawning Windows Script Host removed_in_version: 5.2.0 reason: Detection deprecated as it no longer effectively identifies the intended malicious activity baselines: - content: Previously Seen AWS Cross Account Activity removed_in_version: 5.4.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - content: Previously Seen AWS Cross Account Activity - Initial removed_in_version: 5.4.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - content: Previously Seen AWS Cross Account Activity - Update removed_in_version: 5.4.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - content: Add Prohibited Processes to Enterprise Security removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - content: Baseline of API Calls per User ARN removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - content: Baseline of Excessive AWS Instances Launched by User - MLTK removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - content: Baseline of Excessive AWS Instances Terminated by User - MLTK removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - content: Previously seen API call per user roles in CloudTrail removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - content: Previously Seen AWS Provisioning Activity Sources removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - content: Previously Seen EC2 AMIs removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - content: Previously Seen EC2 Instance Types removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - content: Previously Seen EC2 Launches By User removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - content: Previously seen users in CloudTrail removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - content: Update previously seen users in CloudTrail removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - content: Monitor Successful Backups removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - content: Monitor Unsuccessful Backups removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - content: Previously Seen AWS Regions removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - content: Previously Seen EC2 Modifications By User removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' - content: Systems Ready for Spectre-Meltdown Windows Patch removed_in_version: 5.2.0 reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.' investigations: - content: All backup logs for host removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Amazon EKS Kubernetes activity by src ip removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: AWS Investigate Security Hub alerts by dest removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: AWS Investigate User Activities By AccessKeyId removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: AWS Investigate User Activities By ARN removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: AWS Network ACL Details from ID removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: AWS Network Interface details via resourceId removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: AWS S3 Bucket details via bucketName removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: GCP Kubernetes activity by src ip removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get All AWS Activity From City removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get All AWS Activity From Country removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get All AWS Activity From IP Address removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get All AWS Activity From Region removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get Backup Logs For Endpoint removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get Certificate logs for a domain removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get DNS Server History for a host removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get DNS traffic ratio removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get EC2 Instance Details by instanceId removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get EC2 Launch Details removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get Email Info removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get Emails From Specific Sender removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get First Occurrence and Last Occurrence of a MAC Address removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get History Of Email Sources removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get Logon Rights Modifications For Endpoint removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get Logon Rights Modifications For User removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get Notable History removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get Outbound Emails to Hidden Cobra Threat Actors removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get Parent Process Info removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get Process File Activity removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get Process Info removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get Process Information For Port Activity removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get Process Responsible For The DNS Traffic removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get Sysmon WMI Activity for Host removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Get Web Session Information via session id removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Investigate AWS activities via region name removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Investigate AWS User Activities by user field removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Investigate Failed Logins for Multiple Destinations removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Investigate Network Traffic From src ip removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Investigate Okta Activity by app removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Investigate Okta Activity by IP Address removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Investigate Pass the Hash Attempts removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Investigate Pass the Ticket Attempts removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Investigate Previous Unseen User removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Investigate Successful Remote Desktop Authentications removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Investigate Suspicious Strings in HTTP Header removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Investigate User Activities In Okta removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' - content: Investigate Web POSTs From src removed_in_version: 5.2.0 reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.' stories: - content: Nexus APT Threat Activity removed_in_version: 5.4.0 reason: Analytic Story has been replaced by a new analytic story with a more specific name replacement_content: - China-Nexus Threat Activity - content: Earth Estries removed_in_version: 5.4.0 reason: Analytic Story has been replaced by a new analytic story with a more specific name replacement_content: - Salt Typhoon - content: AWS Cross Account Activity removed_in_version: 5.4.0 reason: All associated detections with this story have been deprecated - content: AWS Cryptomining removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Cloud Cryptomining - content: AWS Suspicious Provisioning Activities removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Suspicious Cloud Provisioning Activities - content: Common Phishing Frameworks removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - content: Container Implantation Monitoring and Investigation removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Kubernetes Security - content: Host Redirection removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - content: Kubernetes Sensitive Role Activity removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Kubernetes Security - content: Lateral Movement removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Compromised User Account - content: Monitor Backup Solution removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - content: Monitor for Unauthorized Software removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - content: Office 365 Detections removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Office 365 Account Takeover - content: Spectre And Meltdown Vulnerabilities removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity - content: Suspicious AWS EC2 Activities removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Suspicious Cloud Instance Activities - content: Unusual AWS EC2 Modifications removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity replacement_content: - Suspicious Cloud Instance Activities - content: Web Fraud Detection removed_in_version: 5.2.0 reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity